01 Oct 2026
by Nadiia Hulchuk

AI in cyber security: from evolving threats to automated defence

Guest blog by Nadiia Hulchuk, Business Development Manager at SoloWay Technologies #AISecurity

The advent of artificial intelligence has changed all the rules of the game, including in cybersecurity. It serves as both a powerful shield for defenders and a dangerous weapon for malicious actors.

AI and cyber security: risk or opportunity?

Artificial intelligence makes cyberattacks larger in scale, faster, and much harder to detect. The technical barrier to breaching secure systems has dropped dramatically. In fact, anyone with access to an AI tool and the intent to commit a cybercrime can now do so. Cybercriminals cannot only automate attacks easily, but also generate malicious code in minutes.

However, artificial intelligence is equally essential to defence, giving organisations advanced tools to detect and protect against malicious attacks. In cybersecurity, AI identifies vulnerabilities, analyses massive datasets, automates responses to emerging threats, and recognises patterns that indicate malicious activity.

Artificial intelligence is a two-sided coin — serving as both a threat and an opportunity. At its core, AI is a tool whose impact depends entirely on human intent, raising a critical question: could AI eventually begin acting maliciously on its own initiative?

What AI precedents have occurred in the UK?

Over the past year, AI-driven security incidents in the UK have escalated to unprecedented levels. According to a recent , more than one in five UK security breaches involve artificial intelligence. AI-powered impersonation was the most common attack type (45% of all cases), followed by malware and AI-leveraged phishing campaigns (19% and 17%, respectively).

IBM Study More Than One in Five Malicious UK Breaches are AI Generated.png

UK Cyber Threat Landscape (based on data presented in the article “IBM Study: More Than One in Five Malicious UK Breaches are AI Generated”)

UK Cyber Threat Landscape (based on data presented in the article )

UK fraud prevention service 444,000 fraud cases over the past year, with AI increasingly driving these attacks. Mobile devices, online purchases, and credit cards remained the primary vectors for account takeover scams. that AI will increasingly enable highly personalised cyberattacks and long-term synthetic identities. This shift underscores the need for cross-sector collaboration to catch early indicators of compromise.

A new wave of concern has emerged over the autonomous, unlawful actions of artificial intelligence. these evolving cyber security challenges after incidents in which advanced language models compromised enterprise systems. While developers stepped in during those 16% of instances where testing ran amok (19 of 122 evaluations), the Institute cautions that safeguards remain lax across both public-facing tools and high-capability frontier models.

Balancing risk and defense: how AI can be used to prevent cybercrime

While AI poses significant cybersecurity threats, it can also strengthen defences. Generative AI is a branch of machine learning that can produce diverse content types, including code, video, text, and images. This core capability enables fundamentally new approaches to cybersecurity. However, these systems rely on massive training datasets to identify patterns and generate effective defensive responses.

Here is how :

  1. Threat identification and analysis. AI algorithms establish baseline employee behaviour and immediately flag suspicious activity — such as an off-hours access attempt to confidential files from an unrecognised device.

  2. Automating core security tasks. Generative AI can automate routine security operations by generating code and updating system configurations with minimal human intervention. It can write custom deployment scripts to patch vulnerabilities across dozens of endpoints simultaneously.

  3. Threat and vulnerability modeling. AI can simulate sophisticated cyber-attacks to evaluate organisational resilience and pinpoint system vulnerabilities. These automated exercises also play a key role in security awareness training, helping staff recognize phishing tactics and complex social engineering schemes.

Sources referenced


Cyber Resilience Programme activities

techUK brings together key players across the cyber security sector to promote leading-edge UK capabilities, build networks and grow the sector. techUK members have the opportunity to network, share ideas and collaborate, enabling the industry as a whole to address common challenges and opportunities together. Visit the programme page here.

 

Upcoming events

Latest news and insights 

Learn more and get involved

 

Cyber Resilience updates

Sign-up to get the latest updates and opportunities from our Cyber Resilience programme.

 

 

Here are the five reasons to join the Cyber Resilience programme

Download

Join techUK groups

techUK members can get involved in our work by joining our groups, and stay up to date with the latest meetings and opportunities in the programme.

Learn more

 

Become a techUK member

Our members develop strong networks, build meaningful partnerships and grow their businesses as we all work together to create a thriving environment where industry, government and stakeholders come together to realise the positive outcomes tech can deliver.

Learn more

 

 Meet the team 

Jill Broom

Jill Broom

Head of Cyber Resilience, techUK

Jill leads the techUK Cyber Resilience programme, having originally joined techUK in October 2020 as a Programme Manager for the Cyber and Central Government programmes. She is responsible for managing techUK's work across the cyber security ecosystem, bringing industry together with key stakeholders across the public and private sectors. Jill also provides the industry secretariat for the Cyber Growth Partnership, the industry and government conduit for supporting the growth of the sector. A key focus of her work is to strengthen the public–private partnership across cyber to support further development of UK cyber security and resilience policy.

Before joining techUK, Jill worked as a Senior Caseworker for an MP, advocating for local communities, businesses and individuals, so she is particularly committed to techUK’s vision of harnessing the power of technology to improve people’s lives. Jill is also an experienced editorial professional and has delivered copyediting and writing services for public-body and SME clients as well as publishers.

Email:
[email protected]
Website:
www.techuk.org/
LinkedIn:
https://www.linkedin.com/in/jill-broom-19aa824

Read lessmore

Annie Collings

Annie Collings

Senior Programme Manager, Cyber Resilience, techUK

Annie is the Programme Manager for Cyber Resilience at techUK. She first joined as the Programme Manager for Cyber Security and Central Government in September 2023. 

In her role, Annie supports the Cyber Security SME Forum, engaging regularly with key government and industry stakeholders to advance the growth and development of SMEs in the cyber sector. Annie also coordinates events, engages with policy makers and represents techUK at a number of cyber security events.

Before joining techUK, Annie was an Account Manager at a specialist healthcare agency, where she provided public affairs support to a wide range of medical technology clients. She also gained experience as an intern in both an MP’s constituency office and with the Association of Independent Professionals and the Self-Employed. Annie holds a degree in International Relations from Nottingham Trent University.

Email:
[email protected]
Twitter:
anniecollings24
LinkedIn:
https://www.linkedin.com/in/annie-collings-270150158/

Read lessmore

Olivia Staples

Olivia Staples

Junior Programme Manager - Cyber Resilience, techUK

Olivia Staples joined techUK in May 2025 as a Junior Programme Manager in the Cyber Resilience team.

She supports the programs mission to promote cyber resilience by engaging key commercial and government stakeholders to shape the cyber resilience policy towards increased security and industry growth. Olivia assists in member engagement, event facilitation and communications support.

Before joining techUK, Olivia gained experience in research, advocacy, and strategic communications across several international organisations. At the Munich Security Conference, she supported stakeholder engagement and contributed to strategic communications. She also worked closely with local and national government stakeholders in Spain and Italy, where she was involved in policy monitoring and advocacy for both public and private sector clients.

Olivia holds an MSc in Political Science (Comparative Politics and Conflict Studies) from the London School of Economics (LSE) and a BA in Spanish and Latin American Studies from University College London (UCL).

Outside of tech, Olivia enjoys volunteering with local charities and learning Norwegian.

Email:
[email protected]

Read lessmore

 

 

 

 

Authors

Nadiia Hulchuk

Nadiia Hulchuk

Business Development Manager, SoloWay Technologies